VYPR

Elefant CMS

by Elefantcms

CVEs (7)

  • CVE-2017-20064MedJun 20, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version…

  • CVE-2017-20063MedJun 20, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege management. It is possible to launch the attack…

  • CVE-2017-20062MedJun 20, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…

  • CVE-2017-20061MedJun 20, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site…

  • CVE-2017-20057MedJun 20, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version…

  • CVE-2017-20060LowJun 20, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading…

  • CVE-2017-20059LowJun 20, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input leads to basic cross site…